CVE-2026-3257: Tokuhirom Unqlite

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl embeds the UnQLite library. Version 0.06 and earlier of the Perl module uses a version of the library from 2014 that may be vulnerable to a heap-based overflow.

Affected products

  • Tokuhirom Unqlite: before 0.07 (fixed in 0.07)

Published 2026-03-05. Last modified 2026-06-17.